logo

Node.js Patches Memory Leak and Permission Bypasses

ID: e60bba6a-d9bc-5950-aeaf-f1a645944759

STIX ID: report--e60bba6a-d9bc-5950-aeaf-f1a645944759

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Node.js published critical security updates across active release lines (25.x, 24.x, 22.x, 20.x) fixing eight vulnerabilities (three high, four medium, one low). The most serious, CVE-2025-55131, is a memory allocation/race condition that can leave buffers containing leftover data and potentially leak in-process secrets (tokens/passwords), especially when using the vm module with timeouts; two other flaws allow permission-model bypasses via crafted symlink paths and Unix Domain Sockets. The release also addresses multiple DoS crash vectors; developers are urged to upgrade to the patched versions to prevent data leaks and service disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.